The Next Frontier to explore: AIGSI, Artificial Governance Standard of India

FDPPI has already published several frameworks for DPDPA Compliance.

FDPPI had introduced a separate framework “DGPSI-AI” to cover the requirements of DPDPA Compliance by Data Fiduciaries who deploy AI for processing of personal information. This is now integrated with the DGPSI-Full version as a standard extension. This covered 6 principles, 9 implementation specifications for deployers and 13 implementation specifications for developers.

However, in the recent days additional compliance requirements have arisen because RBI has issued a “Model Risk Management Framework” and “Data Governance Framework” and CERT IN has issued its own AI Framework for Risk management. Hence it has become necessary to expand the DGPSI-AI from the DPDPA environment to a larger Data Governance framework.

In this context FDPPI is exploring the development of a framework for AI Governance in the form of  AIGSI or the Artificial Intelligence Governance Standard of India.

It is clarified that this is a suggested framework designed by the Private Sector in India as a Best Practice guideline. As and when a specific law emerges in this sector, the framework will be suitably fine tuned.

Currently the framework has

  • 12 principles covering accountability, risk-tiering, explainability, security-by-design, human oversight and lifecycle governance.
  • 30 specifications, in 6 clusters, for the organisation putting an AI model to use.
  • 31 specifications, in 7 clusters, for whoever builds or supplies the model.

Following are the 12 principles

1 Accountability Through a Human Handler Behind every AI algorithm there shall be one identifiable human accountable for its outcomes, on both the deployer and developer sides.
2 Unknown Risk is Significant Risk Where an AI system’s behaviour or risk cannot be fully known or explained, it shall by default be treated as a significant/high risk requiring enhanced governance.
3 Explainability by Design Every privacy notice or disclosure covering an AI process shall be accompanied by an explainability disclosure; higher-impact models require higher explainability thresholds, and where full explainability is not achievable, compensating controls apply.
4 Justified Use, Not Default Use The use of an AI process shall be validated by a document justifying the technical, operational and economic need, at both the deployer and developer ends, before it is put to use against a data principal.
5 Guardrails Against Dark Patterns and Harm Every AI process shall document the specific guardrails securing the processing against dark patterns, neurological manipulation, and physical or psychological harm to any data principal.
6 Fiduciary Responsibility to Society The deployer, as fiduciary, shall ensure all measures necessary to safeguard society at large from adverse effects arising from the use of AI — not the individual data principal alone.
7 Risk-Based, Tiered Governance The intensity of governance — validation frequency, approval authority, monitoring and documentation — shall be proportionate to a model’s materiality, complexity, autonomy and the degree of reliance placed on its output.
8 Independent Validation and Challenge All models, including third-party and AI/ML models, shall be subject to independent validation or audit by a function distinct from the team that built, owns or commercially benefits from the model, following a three-lines-of-defence structure.
9 Human Oversight and Override Human-in-command arrangements, override/suspension/kill-switch mechanisms, and periodic human review of AI-driven decisions shall be maintained, with explicit safeguards against automation bias and decision fatigue.
10 Security and Integrity by Design AI systems and the infrastructure they run on shall be built and operated under a Secure Development Lifecycle, with continuous vulnerability assessment (including AI-assisted testing), access control and credential hygiene.
11 Timely, Transparent Disclosure Vulnerabilities, security incidents and material model risks shall be disclosed to affected stakeholders and to the relevant regulator (Data Protection Board / CERT-In / RBI) within defined timeframes, without waiting for a complete post-mortem.
12 Lifecycle Governance and Continual Improvement AI governance is not a one-time certification. Models shall be governed across their full lifecycle — selection, development, validation, approval, deployment, monitoring, change management and decommissioning — with records retained well beyond decommissioning.

The implementation specifications for deployers consist of 30 controls divided into six clusters. The implementation specifications for developers consist of 31 controls divided into 7 clusters.

The Six clusters of the Deployer part of the framework are as follows:

A. Governance and Accountability

B. Risk Assessment and Classification

C. Vendor and Developer Due Diligence

D. Deployment Controls and Human Oversight

E. Monitoring and Change management

F. Documentation, Audit and Regulatory Engagement

The 31 implementation specifications for Developers are divided into the following seven clusters

A. Explainability, Documentation and Risk Disclsoure

B. Testing, Security and Secure Development

C. Vulnerability Management and Patch Response

D. Credential and Access Management

E. Incident Response and Transparency

F: Safety Controls

G: Deliverables to Deployers and Regulators

 A Complete document of the framework is available here. 

The framework is currently under discussion. Comments are welcome.

Naavi

Posted in Privacy | Leave a comment

Beyond the frontiers of DPDPA 2023

After successfully concluding the three day training program for Certified Independent Data Auditors, FDPPI is moving to Chennai to conduct a day long symposium in association with MMA on “Beyond the Frontiers of DPDPA”.

Interesting topic to be discussed during the program include AIGSI (AI Governance Standard of India), DGPSI-Banks, (Data Governance and Protection Standard of India-Banks”) and “Role of Independent Data Auditors”.

We look forward to your participation.

Register here

Naavi

Posted in Privacy | Leave a comment

Contact secretary@aidai.org.in for registration

Posted in Privacy | Leave a comment

Mock DPB Hearing at Bangalore on August 23

DPDPA Rules have been notified on November 13, 2025. The first task before the Data Protection Board will commence from 13th November 2026 which is hardly 88 days away. This is the date set for submission of applications by aspiring “Consent Managers” for accreditation.

Before this date, DPB must be in place and its website should be operative with a necessary application form. The aspiring entities whether they are TCS, or JIO or IDFY or any other entity should get their platform audited and certified by an independent auditor of relevant credentials.

However, so far no developments have taken place so far to indicate that the Government is getting ready. In the meantime Supreme Court has received a petition challenging the constitutionality of the Act which could be a reason for the Government to be keeping the DPB formation in abeyance.

Nevertheless, for Naavi and FDPPI, it is time to continue their training efforts to create DPOs and Data Auditors ready to take on their respective responsibilities when the time comes.

In this direction, the next training program for Certified Independent Data Auditors (CIDA) is happening as a 3 day program at Fairfield Marriott, Rajaji Nagar, Bengaluru.

A virtual curtain raiser program concluded yesterday with a discussion on DPDPA and responsibilities of a DPO for implementation and the physical event is set to commence on August 23rd.

Marking the uniqueness of the training, a mock DPB hearing has been scheduled as a part of the training with a role play. The hearing will discuss the complaint of a Bank Customer against a Bank using an AI model to reject her loan application. The purpose of the discussion is to bring home learning points on DPDPA, RBI guidelines on AI, AI Governance requirements etc.

It should be an interesting experience for the trainees.

Look forward to this eventful interaction.

Considering the importance of this event, FDPPI is inviting representatives of MeitY to be present if possible. FDPPI has been regularly inviting MeitY for such programs and they are consistently avoiding attendance. We hope this time it would be different.

Naavi

Posted in Privacy | Leave a comment

Let this poster adorn corporate walls

Posted in Privacy | Leave a comment

Be one of the first few to prefix your name with IDA

Those who pass the examination after CIDA training are entitled to use the title “IDA” as a prefix to their name. Collect the IDA badge by completing the course in the first cohort.

Naavi

Posted in Privacy | Leave a comment